# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=92

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 93

---

## [Java API Client Convert Query back to builder or Parent Builder class](https://discuss.elastic.co/t/java-api-client-convert-query-back-to-builder-or-parent-builder-class/363634)

<div class="topic-metadata">

**Author:** [@Vijeya\_Nidhi](https://discuss.elastic.co/u/Vijeya_Nidhi)\
**Replies:** 1\
**Last updated:** [July 24, 2024, 9:54am UTC](https://discuss.elastic.co/t/java-api-client-convert-query-back-to-builder-or-parent-builder-class/363634 "2024-07-24T09:54:11Z")

</div>

Hi, in the new java api client Is there any method to convert Query back to its builder format ie Query.Builder, BoolQuery.Builder etc to add more conditions (like adding more must conditions) into it? or is there any…

---

## [Term query is case sensitive for some but not for others](https://discuss.elastic.co/t/term-query-is-case-sensitive-for-some-but-not-for-others/363646)

<div class="topic-metadata">

**Author:** [@paulmuller](https://discuss.elastic.co/u/paulmuller)\
**Replies:** 3\
**Last updated:** [July 24, 2024, 8:02am UTC](https://discuss.elastic.co/t/term-query-is-case-sensitive-for-some-but-not-for-others/363646 "2024-07-24T08:02:10Z")

</div>

What could be the reason that a term query behaves case sensitive in some installations and case insensitive in others? In the mapping the affected field is of type keyword. Both installations use the same Docker Compose…

---

## [Filtering on aggregations](https://discuss.elastic.co/t/filtering-on-aggregations/362130)

<div class="topic-metadata">

**Author:** [@Navnath](https://discuss.elastic.co/u/Navnath)\
**Replies:** 2\
**Last updated:** [July 24, 2024, 5:51am UTC](https://discuss.elastic.co/t/filtering-on-aggregations/362130 "2024-07-24T05:51:01Z")

</div>

Hello, I am doing a search operation to get some product results with their associated aggregations. So , here, aggregations are by products of the search result When I fetch this result, I ask for only 100 aggregatio…

---

## [Often hot node require restart](https://discuss.elastic.co/t/often-hot-node-require-restart/363484)

<div class="topic-metadata">

**Author:** [@mohd\_sa](https://discuss.elastic.co/u/mohd_sa)\
**Replies:** 2\
**Last updated:** [July 23, 2024, 5:18pm UTC](https://discuss.elastic.co/t/often-hot-node-require-restart/363484 "2024-07-23T17:18:24Z")

</div>

i have 3 master and one hot node and warm node , often injest data on hot node is decrease and after restart elasticsearch service , It works correctly. I don't understand why

---

## [Present end of nested field as a part of value](https://discuss.elastic.co/t/present-end-of-nested-field-as-a-part-of-value/363643)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 2\
**Last updated:** [July 23, 2024, 4:54pm UTC](https://discuss.elastic.co/t/present-end-of-nested-field-as-a-part-of-value/363643 "2024-07-23T16:54:31Z")

</div>

Hi, I have records which could contain nested fields with a high depth. And I want to convert part of the nested field to the part of the value. What I have before { "a":{ "b":{ "c":{ "d":{ …

---

## [\[Bug\]: ElasticSearch : Timeout context manager should be used inside a task](https://discuss.elastic.co/t/bug-elasticsearch-timeout-context-manager-should-be-used-inside-a-task/363639)

<div class="topic-metadata">

**Author:** [@FlorentGrenier](https://discuss.elastic.co/u/FlorentGrenier)\
**Replies:** 1\
**Last updated:** [July 23, 2024, 3:24pm UTC](https://discuss.elastic.co/t/bug-elasticsearch-timeout-context-manager-should-be-used-inside-a-task/363639 "2024-07-23T15:24:03Z")

</div>

Bug Description I'm developing a chatbot, and on a second request sent the bug appears I have llama-index installed in the conda environment with Pyhton 3.12.3. I have streamlit 1.36.0 for UI. I have elastic-transport…

---

## [Documents will not be found with querry, even if querry and mapping is correctand documents contain the fields](https://discuss.elastic.co/t/documents-will-not-be-found-with-querry-even-if-querry-and-mapping-is-correctand-documents-contain-the-fields/363528)

<div class="topic-metadata">

**Author:** [@felix.maier](https://discuss.elastic.co/u/felix.maier)\
**Replies:** 0\
**Last updated:** [July 22, 2024, 7:59am UTC](https://discuss.elastic.co/t/documents-will-not-be-found-with-querry-even-if-querry-and-mapping-is-correctand-documents-contain-the-fields/363528 "2024-07-22T07:59:26Z")

</div>

Hello, I have a Problem to find Documents in a Data Stream. Every Document has the fileds "received\_from" With an Update from the Filebeats, the filed "host.hostname" was added. Bothe of the filds hold the same string, a…

---

## [Aggregation fails silently, returns the default response of 10 docs and hits instead of error](https://discuss.elastic.co/t/aggregation-fails-silently-returns-the-default-response-of-10-docs-and-hits-instead-of-error/362872)

<div class="topic-metadata">

**Author:** [@Laurent\_Martelli](https://discuss.elastic.co/u/Laurent_Martelli)\
**Replies:** 2\
**Last updated:** [July 23, 2024, 10:23am UTC](https://discuss.elastic.co/t/aggregation-fails-silently-returns-the-default-response-of-10-docs-and-hits-instead-of-error/362872 "2024-07-23T10:23:44Z")

</div>

ES / Kibana v 8.14.1 Same as Aggregation fails silently when ran on huge data, instead of error returns the default response of 10 docs and hits I send an aggregation query with "size": 0 example query POST /logstash…

---

## [Nest v7 Support End date?](https://discuss.elastic.co/t/nest-v7-support-end-date/363353)

<div class="topic-metadata">

**Author:** [@bsehra](https://discuss.elastic.co/u/bsehra)\
**Replies:** 2\
**Last updated:** [July 23, 2024, 9:31am UTC](https://discuss.elastic.co/t/nest-v7-support-end-date/363353 "2024-07-23T09:31:23Z")

</div>

Hi All, We are planning to migrate from NEST v7 to .NET Client v8. Since it's going to take some time to completely migrate the whole project. I can see here at this link that "v7 NEST client continues to be supported"…

---

## [How to set up third party https requests to Elasticsearch](https://discuss.elastic.co/t/how-to-set-up-third-party-https-requests-to-elasticsearch/363560)

<div class="topic-metadata">

**Author:** [@Knut\_Knackwurst](https://discuss.elastic.co/u/Knut_Knackwurst)\
**Replies:** 2\
**Last updated:** [July 23, 2024, 8:40am UTC](https://discuss.elastic.co/t/how-to-set-up-third-party-https-requests-to-elasticsearch/363560 "2024-07-23T08:40:14Z")

</div>

Hi, I followed both of these tutorials: Set up basic security for the Elastic Stack and Set up basic security for the Elastic Stack plus secured HTTPS traffic. Now i want to set up the ability for a third party app (I …

---

## [\[6.7.1\]how to set ccs with kerberos](https://discuss.elastic.co/t/6-7-1-how-to-set-ccs-with-kerberos/363546)

<div class="topic-metadata">

**Author:** [@lammm4](https://discuss.elastic.co/u/lammm4)\
**Replies:** 9\
**Last updated:** [July 23, 2024, 3:25am UTC](https://discuss.elastic.co/t/6-7-1-how-to-set-ccs-with-kerberos/363546 "2024-07-23T03:25:17Z")

</div>

we use es 6.7.1 with kerberos, but after set remote cluster, the state connect is always false, and the seeds is empty. does it support ccs with using kerberos?

---

## [Docker Swarm + Traefik - master not discovered when open ports 9200 and 9300](https://discuss.elastic.co/t/docker-swarm-traefik-master-not-discovered-when-open-ports-9200-and-9300/363574)

<div class="topic-metadata">

**Author:** [@ciocan](https://discuss.elastic.co/u/ciocan)\
**Replies:** 2\
**Last updated:** [July 22, 2024, 9:56pm UTC](https://discuss.elastic.co/t/docker-swarm-traefik-master-not-discovered-when-open-ports-9200-and-9300/363574 "2024-07-22T21:56:25Z")

</div>

Once I open ports on es03 the elasticsearch node can't communicate with others. Here is the compose file: version: '3.9' services: setup: image: ${ELASTIC\_IMAGE}:${STACK\_VERSION} networks: - esnet …

---

## [Nested query](https://discuss.elastic.co/t/nested-query/363549)

<div class="topic-metadata">

**Author:** [@shrm](https://discuss.elastic.co/u/shrm)\
**Replies:** 4\
**Last updated:** [July 22, 2024, 9:12pm UTC](https://discuss.elastic.co/t/nested-query/363549 "2024-07-22T21:12:23Z")

</div>

I have an index for a country list as: { "countries": { "mappings": { "properties": { "cities": { "type": "nested", "properties": { "id": { "type": "inte…

---

## [Logstash + TG](https://discuss.elastic.co/t/logstash-tg/362776)

<div class="topic-metadata">

**Author:** [@TatianaKlimova91](https://discuss.elastic.co/u/TatianaKlimova91)\
**Replies:** 8\
**Last updated:** [July 22, 2024, 8:11pm UTC](https://discuss.elastic.co/t/logstash-tg/362776 "2024-07-22T20:11:27Z")

</div>

Hi there! I try to set logstash.config to send alerts to telegram bot. I added in output section http part and recreated logstash container, but still can’t get alerts. Locally from api alerts are working. Logstash pl…

---

## [Best practice for managing many log formats with data streams](https://discuss.elastic.co/t/best-practice-for-managing-many-log-formats-with-data-streams/363376)

<div class="topic-metadata">

**Author:** [@DCraddockPOR](https://discuss.elastic.co/u/DCraddockPOR)\
**Replies:** 5\
**Last updated:** [July 22, 2024, 7:00pm UTC](https://discuss.elastic.co/t/best-practice-for-managing-many-log-formats-with-data-streams/363376 "2024-07-22T19:00:08Z")

</div>

Apologies if this is a redundant topic of conversation; I feel I've searched far and wide and can't find a clear answer. And, if it isn't obvious, I'm new to the Elastic ecosystem. I have many different log formats that…

---

## [Update entire documents](https://discuss.elastic.co/t/update-entire-documents/363585)

<div class="topic-metadata">

**Author:** [@jane\_manuel](https://discuss.elastic.co/u/jane_manuel)\
**Replies:** 0\
**Last updated:** [July 22, 2024, 5:43pm UTC](https://discuss.elastic.co/t/update-entire-documents/363585 "2024-07-22T17:43:17Z")

</div>

hello, i have an elastic instance with more than 100 million document, i have a date field with different format on each document, so i want to update all the documents to have a unified date format i am using somethin…

---

## [Latency in seeing a document](https://discuss.elastic.co/t/latency-in-seeing-a-document/363071)

<div class="topic-metadata">

**Author:** [@siakc](https://discuss.elastic.co/u/siakc)\
**Replies:** 42\
**Last updated:** [July 22, 2024, 3:59pm UTC](https://discuss.elastic.co/t/latency-in-seeing-a-document/363071 "2024-07-22T15:59:16Z")

</div>

It seems to be a delay between the time a doc is put and the time it is searchable in the Kibana. I wanted to find the reason. "indexing": { "index\_total": 3568228, "index\_time\_in\_millis": 1947151,…

---

## [Nested Field exists check not working as expected](https://discuss.elastic.co/t/nested-field-exists-check-not-working-as-expected/356859)

<div class="topic-metadata">

**Author:** [@Sankar\_S](https://discuss.elastic.co/u/Sankar_S)\
**Replies:** 8\
**Last updated:** [July 22, 2024, 3:28pm UTC](https://discuss.elastic.co/t/nested-field-exists-check-not-working-as-expected/356859 "2024-07-22T15:28:37Z")

</div>

GET index1/\_search { "query": { "bool": { "must\_not": \[ { "nested": { "path": "publish\_details", "query": { "bool": { "must\_not": \[ …

---

## [ILM delete policy and kibana scripted fields](https://discuss.elastic.co/t/ilm-delete-policy-and-kibana-scripted-fields/363567)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 0\
**Last updated:** [July 22, 2024, 2:38pm UTC](https://discuss.elastic.co/t/ilm-delete-policy-and-kibana-scripted-fields/363567 "2024-07-22T14:38:35Z")

</div>

Hello team, The documentation on ILM rollover policy is saying that, for indices that have document updates, whenever a rollover triggered, a new write index is created, and the updates are happening in that new index M…

---

## [Kibana - Filtering by buckets](https://discuss.elastic.co/t/kibana-filtering-by-buckets/361745)

<div class="topic-metadata">

**Author:** [@Knut\_Knackwurst](https://discuss.elastic.co/u/Knut_Knackwurst)\
**Replies:** 3\
**Last updated:** [July 22, 2024, 2:28pm UTC](https://discuss.elastic.co/t/kibana-filtering-by-buckets/361745 "2024-07-22T14:28:38Z")

</div>

Hello! First of all, let me describe my data source: I have business items that run through multiple processes. I've got a historic SQL table, in which all actions (item status changed, item processed, item viewed,...…

---

## [2 way search by query and incoming docs](https://discuss.elastic.co/t/2-way-search-by-query-and-incoming-docs/363170)

<div class="topic-metadata">

**Author:** [@elsaticnoob](https://discuss.elastic.co/u/elsaticnoob)\
**Replies:** 15\
**Last updated:** [July 22, 2024, 12:17pm UTC](https://discuss.elastic.co/t/2-way-search-by-query-and-incoming-docs/363170 "2024-07-22T12:17:36Z")

</div>

I am working on an app where the goal is to find likeminded people in your area, nothing revolutionary. Given a user's age, minAge,maxAge fields, we want to query for other docs that meet the criteria. However, the sear…

---

## [elasticsearch updateByQuery is not working for large data](https://discuss.elastic.co/t/elasticsearch-updatebyquery-is-not-working-for-large-data/363485)

<div class="topic-metadata">

**Author:** [@Karan\_Rawat](https://discuss.elastic.co/u/Karan_Rawat)\
**Replies:** 3\
**Last updated:** [July 22, 2024, 11:21am UTC](https://discuss.elastic.co/t/elasticsearch-updatebyquery-is-not-working-for-large-data/363485 "2024-07-22T11:21:52Z")

</div>

i have written a script that will create a key "source" on 4 indices of elasticsearch based on some condition . All of my 4 indices contain at least 2~3 million data . when i ran the script it added the key for only 3 en…

---

## [I install elasticsearch 8 in vps serverusing rpm in almalinux but elasticsearch8 not working it showing error](https://discuss.elastic.co/t/i-install-elasticsearch-8-in-vps-serverusing-rpm-in-almalinux-but-elasticsearch8-not-working-it-showing-error/363543)

<div class="topic-metadata">

**Author:** [@Rahul\_Sharma3](https://discuss.elastic.co/u/Rahul_Sharma3)\
**Replies:** 0\
**Last updated:** [July 22, 2024, 10:09am UTC](https://discuss.elastic.co/t/i-install-elasticsearch-8-in-vps-serverusing-rpm-in-almalinux-but-elasticsearch8-not-working-it-showing-error/363543 "2024-07-22T10:09:15Z")

</div>

I install elasticsearch 8 in vps server using rpm in almalinux but elasticsearch8 not working it showing no issue when using this command : curl -XGET "localhost:9200" but in after that when i execute : curl -XGET 'loca…

---

## [Getting Error on creating embedding via code](https://discuss.elastic.co/t/getting-error-on-creating-embedding-via-code/363530)

<div class="topic-metadata">

**Author:** [@Shubham\_Pandey1](https://discuss.elastic.co/u/Shubham_Pandey1)\
**Replies:** 1\
**Last updated:** [July 22, 2024, 9:19am UTC](https://discuss.elastic.co/t/getting-error-on-creating-embedding-via-code/363530 "2024-07-22T09:19:04Z")

</div>

function to create vector embeddings : - async getVectorEmbedding(text) { try { const response = await this.client.ingest.simulate({ body: { pipeline: { id: process.env.INGEST\_PIP…

---

## [Applying ILM for backing indices of Elastic Integrations' datastreams](https://discuss.elastic.co/t/applying-ilm-for-backing-indices-of-elastic-integrations-datastreams/363533)

<div class="topic-metadata">

**Author:** [@An\_Hoang](https://discuss.elastic.co/u/An_Hoang)\
**Replies:** 0\
**Last updated:** [July 22, 2024, 8:34am UTC](https://discuss.elastic.co/t/applying-ilm-for-backing-indices-of-elastic-integrations-datastreams/363533 "2024-07-22T08:34:24Z")

</div>

Hello everyone, I am trying to apply the ILM for the backing indices of Elastic Integrations' datastreams. I see that we have a separate built-in Lifecycle of datastream to set the retention of data. The problem is I wa…

---

## [Master Node vs Data Node](https://discuss.elastic.co/t/master-node-vs-data-node/363403)

<div class="topic-metadata">

**Author:** [@elk.admin](https://discuss.elastic.co/u/elk.admin)\
**Replies:** 3\
**Last updated:** [July 22, 2024, 6:58am UTC](https://discuss.elastic.co/t/master-node-vs-data-node/363403 "2024-07-22T06:58:49Z")

</div>

I have designed a 6 node elasticsearch cluster with 3 Master Nodes and 3 Data nodes. I am trying to turn on the monitoring using Metricbeat . And metricbeat asks for the url of the monitoring Cluster. What should be the …

---

## [Brain Twister (for us any way!)](https://discuss.elastic.co/t/brain-twister-for-us-any-way/363456)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 2\
**Last updated:** [July 21, 2024, 6:53pm UTC](https://discuss.elastic.co/t/brain-twister-for-us-any-way/363456 "2024-07-21T18:53:51Z")

</div>

we have an index and we use it to show documents which we retreive on a paged basis. i.e the query will be { .From((page - 1) \* pageSize) .Size(25) .Sort(sort =\> //etc } How can we figure out if we hav…

---

## [API Key Permissions for Behavioral Analytics](https://discuss.elastic.co/t/api-key-permissions-for-behavioral-analytics/363236)

<div class="topic-metadata">

**Author:** [@jokulicz](https://discuss.elastic.co/u/jokulicz)\
**Replies:** 1\
**Last updated:** [July 21, 2024, 5:24pm UTC](https://discuss.elastic.co/t/api-key-permissions-for-behavioral-analytics/363236 "2024-07-21T17:24:55Z")

</div>

I configured Behavioral Analytics using an API key to track analytics from Search UI and I am trying to refine the permissions so the API key only has access to what it needs. I am running an on-premise Elasticsearch in…

---

## [Preserve uniqueness while supporting large amount of data](https://discuss.elastic.co/t/preserve-uniqueness-while-supporting-large-amount-of-data/363500)

<div class="topic-metadata">

**Author:** [@sam10](https://discuss.elastic.co/u/sam10)\
**Replies:** 0\
**Last updated:** [July 21, 2024, 1:21pm UTC](https://discuss.elastic.co/t/preserve-uniqueness-while-supporting-large-amount-of-data/363500 "2024-07-21T13:21:38Z")

</div>

Hi community, I have approximately a few TB of data (few billions of documents) and I want to save them in an elastic manner while preserving the uniqueness of each document. I achieve uniqueness by generating the \_id …

---

## [Filter stop words in simple\_query\_string](https://discuss.elastic.co/t/filter-stop-words-in-simple-query-string/363283)

<div class="topic-metadata">

**Author:** [@jahedi](https://discuss.elastic.co/u/jahedi)\
**Replies:** 5\
**Last updated:** [July 20, 2024, 4:53am UTC](https://discuss.elastic.co/t/filter-stop-words-in-simple-query-string/363283 "2024-07-20T04:53:11Z")

</div>

Hi, I have an index named news\_headline with such mapping: { "mappings": { "properties": { "authors": { "type": "text" }, "category": { "type": "keyword" }, "date": {…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=91)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=93)
